File Search Engine
  • Search
  • Syntax
  • Fields
  • API
  • 5.45.102.182 · virussign.com_20251021_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 250ad21f0384a2631c8a10571c69f61ce82a786a
    SHA256: 837d6996452422932a9df339fae12e3672167ed0c922612d7b1dbe2136976dff
    application/zip
    14.75MB
    2025-10-21 16:05:19 +0000 UTC

  • 5.45.102.182 · virussign.com_20251020_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara RAT_DarkComet From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 5aac463e2b17ed57f8358f80402c29f1e5f90fab
    SHA256: 3932956109225d4eab0e604be8c4721ea39184433a4047beafe4a6dc30963969
    application/zip
    9.56MB
    2025-10-20 16:05:19 +0000 UTC

  • 5.45.102.182 · virussign.com_20251019_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_MEW From AlienVault by ditekSHen
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Unspecified_Malware_Oct16_A From Florian Roth by Florian Roth (Nextron Systems)
    Yara Win32_PUA_Domaiq From ReversingLabs by ReversingLabs
    Download archived sample
    The password is "infected"

    SHA1: 855569b292f6b5c7b59af0c2a0c56d9e9e5a05e7
    SHA256: bb3bdca23fd1873d577f03632a17a8f901c43ad11c1478d7280ec75c8ae1dfbf
    application/zip
    34.90MB
    2025-10-19 16:05:23 +0000 UTC

  • 5.45.102.182 · virussign.com_20251017_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: 7d0036b88b0f962ca6cb03057f85e225935aff69
    SHA256: 370b2635ac2554265be3fa56f8a4b63fa1344f991f1bfecd0536799ef07f4f8f
    application/zip
    10.79MB
    2025-10-17 16:05:20 +0000 UTC

  • 5.45.102.182 · virussign.com_20251007_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Download archived sample
    The password is "infected"

    SHA1: 6bef964967fb8250bfb7156de71026e6d677eaee
    SHA256: b07dabe67fe85263bb7362878e55202b6c42987d4e8e3f5ed96b2fc29210dc5f
    application/zip
    13.88MB
    2025-10-07 16:05:20 +0000 UTC

  • 5.45.102.182 · virussign.com_20251004_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara Win32_Ransomware_Ryuk From ReversingLabs by ReversingLabs
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Download archived sample
    The password is "infected"

    SHA1: 93e06aadf55c1b0d911171cf8ee3ddd55c2aa1d8
    SHA256: 5424a2ee6e888249f61f8f442054cb525ed8d716d4bc3a2a6711be0edcbfb538
    application/zip
    14.99MB
    2025-10-04 16:05:17 +0000 UTC

  • 5.45.102.182 · virussign.com_20251001_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara INDICATOR_EXE_Packed_VMProtect From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Download archived sample
    The password is "infected"

    SHA1: 138a8d458d6faff416837fda111b20a8b7cda073
    SHA256: ef118fb4be3ae7cb69fb612784450c776c30b1aaf73bb4ed6d54fb34f28fc4af
    application/zip
    38.51MB
    2025-10-01 16:05:20 +0000 UTC

  • 5.45.102.182 · virussign.com_20250918_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara SUSP_XORed_MSDOS_Stub_Message From Florian Roth by Florian Roth
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 464af12da826bac1f1b9692d3309a45191669edc
    SHA256: ecfbce16d0bbebcdd496887e899ddf2fb4619a12a1a135f99f98e6aeb3e6cc29
    application/zip
    25.27MB
    2025-09-18 16:05:21 +0000 UTC

  • 5.45.102.182 · virussign.com_20250912_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara SUSP_Imphash_Mar23_2 From Florian Roth by Arnim Rupp (https://github.com/ruppde)
    Yara INDICATOR_EXE_Packed_MPress From AlienVault by ditekSHen
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara IMPLANT_4_v3_AlternativeRule From Florian Roth by Florian Roth (Nextron Systems)
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: ee4470ce89b8b2662d5ce5a33b40a3b0ec9d80d5
    SHA256: a5e3a5df5db97c04f02f98af867bb20e29ca2b40f49646c78da8286d481e4f5c
    application/zip
    25.98MB
    2025-09-12 16:05:26 +0000 UTC

  • 5.45.102.182 · virussign.com_20250910_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara INDICATOR_EXE_Packed_UPolyX From AlienVault by ditekSHen
    Download archived sample
    The password is "infected"

    SHA1: 7b2c8ea3cd2fa29ee3442098c9a669d865b1f989
    SHA256: 2bb1e668a82cf864ec9702a5b5b41d00b001c9ae6877ee2c006cb3254ec513ce
    application/zip
    15.55MB
    2025-09-10 16:05:16 +0000 UTC

  • 5.45.102.182 · virussign.com_20250906_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: e087cf87567cdcf981fb95323921d8d854725b3e
    SHA256: 028d6fe9f4137fd8459a01cb470df2b772cd345ba535fbf342e6ccd5ce4bc00b
    application/zip
    7.76MB
    2025-09-06 16:05:17 +0000 UTC

  • 5.45.102.182 · virussign.com_20250903_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara INDICATOR_EXE_Packed_ConfuserEx From AlienVault by ditekSHen
    Yara Disable_Defender From AbuseCH by iam-py-test
    Download archived sample
    The password is "infected"

    SHA1: ea34f155984528455e8500d460d1304baedaccb9
    SHA256: 059f7389219e464801c1d81317c486af5e1cc3412e7ec6fdc1389656bc21f06d
    application/zip
    28.95MB
    2025-09-03 16:05:19 +0000 UTC

  • 5.45.102.182 · virussign.com_20250902_LimitedFree.zip

    /samples/virussign/

    Germany · netcup GmbH

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara SUSP_XORed_Mozilla From Florian Roth by Florian Roth (Nextron Systems)
    Download archived sample
    The password is "infected"

    SHA1: 24fa57b0bbcb5c146e66fe0fb85bb4ec659f2d19
    SHA256: 136aee57a53d52904643e091094ce267c540fe38f6ece836c44c27c9a1ce4943
    application/zip
    15.92MB
    2025-09-02 16:05:18 +0000 UTC

  • pypi.corp.tevian.ru · capesolo-0.4.11.tar.gz

    /packages/00/9f/0db316e5456dd811fcd3a2aa4d1282ed639aa02af2b0f0a69173fd9d70c1/

    Russia · PVimpelCom

    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara RAT_adWind From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Adzok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Ap0calypse From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_BlackShades From Florian Roth by Brian Wallace (@botnet_hunter)
    Yara RAT_BlueBanana From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Bozok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_ClientMesh From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_DarkComet From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_DarkRAT From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara APT_MAL_Sandworm_Exaramel_Task_Names From Florian Roth by FR/ANSSI/SDO
    Yara MAL_HawkEye_Keylogger_Gen_Dec18 From Florian Roth by Florian Roth (Nextron Systems)
    Yara RAT_JavaDropper From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_LostDoor From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara RAT_Paradox From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_QRat From Florian Roth by Kevin Breen @KevTheHermit
    Yara RAT_ShadowTech From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Sub7Nation From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_unrecom From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Vertex From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara WindowsCredentialEditor From Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: eb3f78bfbca21a885ed281b778fb210d969828d5
    SHA256: f834cbd8fb6edcf50542d4c2f699bfb4105325598c7c1caecbc123a1bfa2e487
    application/octet-stream
    4.37MB
    2024-11-15 12:40:34 +0000 UTC

  • pypi.corp.tevian.ru · capesolo-0.4.11.tar.gz

    /packages/00/9f/0db316e5456dd811fcd3a2aa4d1282ed639aa02af2b0f0a69173fd9d70c1/

    Russia · PVimpelCom

    Yara Disable_Defender From AbuseCH by iam-py-test
    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Yara RAT_adWind From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Adzok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Ap0calypse From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_BlackShades From Florian Roth by Brian Wallace (@botnet_hunter)
    Yara RAT_BlueBanana From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Bozok From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_ClientMesh From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_DarkComet From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_DarkRAT From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara APT_MAL_Sandworm_Exaramel_Task_Names From Florian Roth by FR/ANSSI/SDO
    Yara MAL_HawkEye_Keylogger_Gen_Dec18 From Florian Roth by Florian Roth (Nextron Systems)
    Yara RAT_JavaDropper From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_LostDoor From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara power_pe_injection From Florian Roth by Benjamin DELPY (gentilkiwi)
    Yara RAT_Paradox From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_QRat From Florian Roth by Kevin Breen @KevTheHermit
    Yara RAT_ShadowTech From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Sub7Nation From Florian Roth by Kevin Breen <kevin@techanarchy.net> (slightly modified by Florian Roth to improve performance)
    Yara RAT_unrecom From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara RAT_Vertex From Florian Roth by Kevin Breen <kevin@techanarchy.net>
    Yara WindowsCredentialEditor From Florian Roth
    Download archived sample
    The password is "infected"

    SHA1: eb3f78bfbca21a885ed281b778fb210d969828d5
    SHA256: f834cbd8fb6edcf50542d4c2f699bfb4105325598c7c1caecbc123a1bfa2e487
    application/octet-stream
    4.37MB
    2024-11-15 12:40:34 +0000 UTC

  • 64.225.114.217 · cobalt-strike-beacon.exe

    /demo/av-test/

    United States · DIGITALOCEAN-ASN

    Yara HKTL_CobaltStrike_Beacon_Strings From Florian Roth by Elastic
    Download archived sample
    The password is "infected"

    SHA1: 13fc4ee61acde4a6b8426170bc62b68bd0569f8f
    SHA256: 2b110070a97cb594c99a67803548ed24f3f1edd4ece104c4a7902bf95dba9ae6
    application/x-msdos-program
    4.95MB
    2024-11-03 23:02:18 +0000 UTC